COLDCARD Security Update Fixed firmware is available. Check if you need to migrate your seed. Learn more
NEW
COLDCARD Mk4 has been replaced by Mk5, which keeps the same features and adds an improved screen and keyboard. Learn more →

Get the highlights.

COLDCARD Mk4 with clear case
COLDCARD Mk4 with clear case

Bright Screen

128x64 pixel OLED screen

COLDCARD Mk4 with clear case

Numeric Keypad

Entering a PIN is easy and quick

COLDCARD Mk4 with clear case

Sliding Cover

Protects screen and prevents
hardware implants

COLDCARD Mk4 with clear case

NFC-V Compatible

Tap to transmit all data types

COLDCARD Mk4 with clear case

Ultrasecure

Real crypto security chips

COLDCARD Mk4 with clear case

Let’s have some fun

Secure doesn't have to be boring. The COLDCARD Mk4 comes in a variety of colours to match your style.

Let’s have
some fun

Secure doesn't have to be boring. The COLDCARD Mk4 comes in a variety of colours to match your style.

Shop Colors

Connectivity

Multiple ways to connect
your COLDCARD, all OFF by default

USB-C connector

USB-C Connector

The industry standard for transmitting both data and power over a single cable.

MicroSD card air-gap

AirGap SneakerNET

Maximum security when transferring data between devices.

NFC tap

NFC Tap

Short-range wireless transmission that sends data to a compatible phone.

Virtual disk mode

Virtual Disk

COLDCARD can emulate a USB disk drive, so PSBT files can be transferred with drag-and-drop.

NFC Push Transaction feature

NFC Push
Transaction

Once enabled, PushTX works with any NFC-enabled phone with internet access. No companion app or phone setup. Just tap to broadcast.

COLDCARD Mk4 protective sliding cover

Rugged & Sleek
Protective cover

Like the classic calculators from our childhoods: slide the protective cover down, reverse, and slide back onto the rear. Saves your screen from damage!

Powered by

Sleep Like a Baby
Technology™

Best-in-class security built in all of
our COLDCARD products.

COLDCARD Mk4 with close-up of the secure element area COLDCARD Q screen showing genuine and caution light icons COLDCARD Mk4 showing PIN entry screen Close-up of the COLDCARD circuit board near the marked destruction points MicroSD card and USB power adapter for air-gapped operation Dice used for provable seed generation
  • Q Mk4

    Dual Secure Element for Key Storage

    We find it quite scary that some hardware wallets trust the main microprocessor with their most valuable secrets. Instead, COLDCARD uses two Secure Elements, from different vendors, to protect your Bitcoin.

    Specifically, the COLDCARD uses Microchip's ATECC608 and Maxim's DS28C36B to store the critical master secret: the 24-word seed phrase for your BIP-39 wallet.

    The wallet secret is split across the main microprocessor and two Secure Elements from different vendors. This reduces dependence on any one chip, but it does not eliminate firmware, supply-chain, backup, or operational risk.

  • Q Mk4

    Genuine vs. Caution Lights

    To resist Evil Maids, and other sneaky people with physical access to your COLDCARD, we sign our firmware with a factory key. During boot-up, the firmware's signature, and nearly every byte of flash memory, will be verified and the appropriate Green/Red light set.

    Changing that light's status is actually controlled by dedicated circuitry connected directly to a Secure Element, so a rogue bit of software cannot override it. The circuit for the lights is exposed on the top surface of the product, so any physical tampering by those maids will be visible as well.

  • Q Mk4

    Anti-phishing Words

    The PIN code on COLDCARD is divided into two parts, such as 1234-5678. You first enter 1234 and then you will be shown two words on-screen. Those words are unique to each PIN prefix and COLDCARD. (The secrets used to enforce that come from inside the secure element, and are unknown to the rest of the world.)

    Your job is to memorize those two words, keep them secret, and every time you use the COLDCARD, check them before entering the final 5678 part of your PIN. This protects you against a trojan-horse COLDCARD that looks like yours but cannot know those two words.

  • Q Mk4

    Physical Security

    The carefully designed PCB increases the SE probing difficulty. Our clear case is part of our security model too, so you can look and see if a "hardware implant" has been inserted inside your device.

    Because of the in-depth use of the secure elements, there is no "factory reset" for the COLDCARD. If you forget your COLDCARD PIN, there is nothing we can do except remind you to recycle your e-waste responsibly!

    We've even put a label, "SHOOT THESE", for more effective device destruction... When the time comes.

  • Q Mk4

    Air Gap Operation

    COLDCARD never needs to touch a computer. It can work entirely from a USB power pack or AC power adapter. This includes everything you need to do in the whole life of the product:

    • Initial PIN choosing and setup.

    • Create a seed using fresh device entropy plus required key timing, physical dice, or physical coin input; use the separate advanced Dice Rolls Only workflow; or import an existing secret.

  • Q Mk4

    Bring Your Own Entropy

    Current standard firmware combines fresh device entropy with one required user method: at least 65 key presses with unpredictable timing, 50 physical six-sided-die rolls, or 128 physical coin flips. Dice Rolls Only is a separate advanced workflow requiring 50 rolls for 12 words or 99 for 24 words. Keep every input private and follow the seed-generation instructions.

    Mk4/Mk5 5.6.2 adds View TRNG Words and offline verification of dice-roll or coin-flip mixing with verify_seed_mix.py. The tool does not support key mashing.

Trick Pin

Trick PIN Features

COLDCARD has even more tricks up its sleeve!

xkcd comic about security
xkcd #538

Duress PIN

You may define an optional "duress PIN code". If anyone enters that PIN code, instead of the "real" PIN code, nothing special is shown on the screen and everything operates as normal... However, the bitcoin key generated is not the main key. It is effectively a completely separate wallet!

To take best advantage of this feature, you should put some Bitcoin into the duress wallet. How much you are willing to lose or what you need to make it plausible, we don't know.

The "duress" wallet will still be derived from the original BIP-39 words, so you don't need to back it up separately, but there will be no way to get from that wallet back to the original wallet with the real funds in it.

Countdown to Brick PIN

This is a covert variation of the BRICK ME PIN mode. It forces a time delay (of minutes/hours/days) when logging into the Coldcard.

But once set, unlike the normal countdown, this special mode covertly bricks the Coldcard (or, optionally merely wipes the seed). Again, this may form some part of your game-theory for duress situations, but is completely optional.

The goal of this mode is to provide plausible deniability for a required time delay, similar to bank safes, while denying the attacker a functional device if they take it away.

BIP-39 Passphrases (25th word)

For any wallet intended to hold an amount whose loss would be materially harmful to you, use a strong, unique BIP-39 passphrase. Back it up separately, record the passphrase wallet fingerprint, and test recovery before depositing funds.

Brick Me PIN

Another PIN can also be defined, which we call the “Brick Me” PIN. Using that PIN code at any PIN prompt will destroy the dual secure element and render your Coldcard worthless. Again, this may form some part of your game-theory for duress situations, but is completely optional.

Login Countdown

Force a time delay when logging into the Coldcard. Once enabled, you must enter the PIN correctly, and then wait out a forced delay (of minutes/hours/days) while a countdown is shown on-screen. Then enter your PIN correctly, a second time, to get in.

xkcd comic about security
xkcd #538

SUPPLY CHAIN PROTECTION

Getting an uncompromised
product into your hands

COLDCARD tamper-evident bag

Unique Bag Number

Each new COLDCARD ships in a numbered tamper-evident bag. The bag number is recorded on the device at the factory and cannot be changed. On first power-up, verify that the number shown on screen matches the numbers printed on the bag and its tear-off tab.

COLDCARD Mk4 clear case

Clear Case

The clear plastic case on COLDCARD is an important feature as well. There have been demonstrations of inserting custom hardware inside a competitor's hardware wallet to capture key presses.

Advanced Features

Temporary Seed and Seed Vault

Temporary seed is a temporary secret completely separate from the master seed, typically held in RAM and not persisted between reboots in the Secure Element.

Seed Vault adds the ability to store multiple temporary secrets in encrypted settings for simple recall and later use. Stored secrets are AES-256-CTR encrypted with your master seed's key.

COLDCARD Co-Signing

COLDCARD Co-Signing (CCC) is a powerful feature that lets you create automated multisig wallets, protected by user-defined spending policies for enhanced security and control.

When enabled, CCC adds a second seed (the Spending Policy Key) to your COLDCARD, which works with your main seed and additional backup keys to create 2-of-N multisig wallets.

The spending policy acts like a hardware security module (HSM), enforcing rules such as transaction limits, spending frequency, whitelisted addresses, and optional 2FA authentication, giving you flexibility while protecting your funds.

LEARN EVEN MORE

Video Walkthroughs

How to Clone/Migrate from Mk4 to COLDCARD Q

Mar 12, 2024

Tutorial: NFC Push Tx

Jun 26, 2024

Tutorial: Applying a Passphrase

Jul 10, 2024

Creating a bitcoin multisig wallet with Nunchuk, TAPSIGNER and COLDCARD

Jun 30, 2023

Spanish guide: COLDCARD Mk4 Tutorial

Jun 29, 2023

Italian guide: Bitcoin Core + COLDCARD

May 30, 2023